Malware

How to remove “Zusy.435323”?

Malware Removal

The Zusy.435323 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.435323 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Zusy.435323?


File Info:

name: B2C725433EFAA260DEDF.mlw
path: /opt/CAPEv2/storage/binaries/0e3a3440a7f0f5248ee3a12f41aa8f4526d32c335a4d6a6ab73e342328815caf
crc32: 0DBAE5FD
md5: b2c725433efaa260dedfac5d6fdfa5ce
sha1: 2e4224b3d5da9641a8f6381d21be35798250009d
sha256: 0e3a3440a7f0f5248ee3a12f41aa8f4526d32c335a4d6a6ab73e342328815caf
sha512: b03e951a48fea89e4706281f94c8054a0f9ffde20077191107895eec99d52a2c4039275903f8ef88375c9fc4c66433b65cbe5f4dd169836cf7fc552ba73d9e13
ssdeep: 12288:GUywFbPxwsZujvtAe76JlDgeIDQlS4nSz7eIa3fyyMhk2VqKoS:j9lxZZupAeC5geEwS4nSzRyalVqKoS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F05AF36B1A3E833C25A49B7EF3AD478D8653D99AD3DE1C127E01B7C5BB2A10550B243
sha3_384: 380863369b9f8a98c75316540f15e9c3c81ebe1c16de5e3314b37855d19b5445e0609db44f40fa61a0f05376a881dd8c
ep_bytes: 558bec83c4f0b8742f4600e8181ffaff
timestamp: 1992-06-19 22:22:17

Version Info:

ProductName: Digitalne dnevne ponude
CompanyName: Alexan hal
FileDescription: Digitalne dnevne ponude
FileVersion: 6.0.0
ProductVersion: 6.0.0
InternalName: WpAR
LegalCopyright: Copyright © Alexander Roshal 1993-2020
OriginalFilename: Win.pdf
Translation: 0x0409 0x04e4

Zusy.435323 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Zusy.435323
FireEyeGen:Variant.Zusy.435323
Cybereasonmalicious.33efaa
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderGen:Variant.Zusy.435323
AvastBackdoorX-gen [Trj]
Ad-AwareGen:Variant.Zusy.435323
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
GoogleDetected
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
RisingTrojan.Generic@AI.87 (RDML:7nAN3KXN1QJRTadohdZgzg)
IkarusTrojan.Inject
FortinetW32/Injector.ERYK!tr
AVGBackdoorX-gen [Trj]

How to remove Zusy.435323?

Zusy.435323 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment